Forum Discussion
Al_Faller_1969
Mar 16, 2011Nimbostratus
Timeouts for LDAP with NPath Routing
Hi All,
I'm attempting to use NPath Routing for a pool of LDAP Servers. I've got it working great, except for an issue with what I'm assuming is an idle timeout. SOme of the LDAP clients (I have no control over them) try to keep a persisant connection to the LDAP server and at some point, the connection is being severed. I'm guessing its the idle timeout on the NPath L4 profile I have? Its currently set at the default of 300 sec. I was considering setting it to slightly over 2 hours, so the keepalive ping from the server (which I believe is 2 hours for linux) would keep any persisent connections open. Do you think this is the cause? DO you think changing the idle timeout would help?
How can I keep an eye on these persisent connections to make sure they don't accumulate too fast?
Thanks in advance!
Al
- hooleylistCirrostratusHi Al,
- Al_Faller_1969NimbostratusHi Aaron,
- HamishCirrocumulusFWIW I used to run a quite large LDAP directory behind F5 LTM's. It isn't uncommon for apps to leave idle connections for many hours and then expect them to be up and running instantly still... 2 hours may be too short.
- coda6_52611NimbostratusI am trying to design a solution for npath routing and AD LDAP services, are your pool members all on the same subent, or are they on different subnets? The articles I found on the KB only give examples for a single subnet.
- nitassEmployeeare your pool members all on the same subent, or are they on different subnets?if i am not wrong, since destination address is not translated, pool member must be in the same subnet as bigip (connected subnet).
- HamishCirrocumulusThat's certainly the easiest... But if something else looked after routing the packet internally to the correct backend, it'd still work... For example you might have two backends reachable via two different routers. As long as the LTM routed them via the separate routers, and the routers passed the packets onto the backends, it'd still work.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects